‹ BackHN Continuity

Thread

What TLA+ can and can't check

243 points · 51 comments · b-man

  1. singron · · focus · HN ↗
    I love this. This is great to read if you are trying to use TLA+ for something.

    In a different vein, another thing TLA+ isn't great at is modeling atomics and in particular weak-memory semantics or anything that's not sequentially consistent. If you translate your algorithm to pcal, it will run as if it was sequentially consistent. If you need to model non-sequential-consistency, then that needs to be spelled out with explicit logic to TLA+, which is probably too complicated and error-prone to do by hand. The C/C++/Rust memory models permit a lot of wacky stuff. I imagine you need to add read caches and writeback buffers for each variable with cache-flushing instructions at appropriate points, but maybe there is a more elegant way to do it.

    If you use rust, miri and loom both have analyzers that can check some non-sequentially-consistent behavior (and loom doesn't actually implement sequential-consistency at all).

    1. anonymousDan · · focus · HN ↗
      For C++ GenMC is probably the state of the art for this: <a href="https:&#x2F;&#x2F;plv.mpi-sws.org&#x2F;genmc&#x2F;" rel="nofollow">https:&#x2F;&#x2F;plv.mpi-sws.org&#x2F;genmc&#x2F;

      There&#x27;s also RustMC for Rust.

Open on Hacker News to reply ↗

Unofficial Hacker News client; not affiliated with Y Combinator.